:OTL [2009/11/19 17:16:28 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll [2009/11/19 17:16:29 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll O3 - HKU\user_ON_C\..\Toolbar\WebBrowser: (no name) - {5BED3930-2E9E-76D8-BACC-80DF2188D455} - No CLSID value found. O3 - HKU\user_ON_C\..\Toolbar\WebBrowser: (no name) - {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - No CLSID value found. O4 - HKU\user_ON_C..\Run: [{9CF93FFF-CDAC-164D-F451-1AB504FCE41B}] File not found O4 - HKU\user_ON_C..\Run: [Fhiwanawozavuyub] C:\WINDOWS\kbhrfskq.dll () O4 - HKU\user_ON_C..\Run: [hewjtfrj] File not found O4 - HKU\user_ON_C..\Run: [smss32.exe] File not found O4 - HKU\user_ON_C..\Run: [wuaucldt] File not found O4 - HKLM..\RunOnceEx: [] File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O7 - HKU\user_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1 O7 - HKU\user_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O7 - HKU\user_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1 O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Temp\679811900.bmp O36 - AppCertDlls: AppSecDll - (C:\Documents and Settings\All Users\Application Data\OcLVneIOUmyW.dll) - C:\Documents and Settings\All Users\Application Data\OcLVneIOUmyW.dll () [2011/03/12 14:10:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Start Menu\Programs\Windows Safemode [2011/03/07 16:10:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Local Settings\Application Data\{EAD11612-EAC2-4DEA-A681-B799BDD48879} [2011/03/07 16:09:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Uwymc [2011/03/07 16:09:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Omlig [2011/03/11 22:36:39 | 000,000,829 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Windows Safemode.lnk [2011/03/07 16:10:56 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Jtuzewehap.dat [2011/03/07 16:10:56 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Qrawejesux.bin [2011/02/26 12:08:14 | 000,398,760 | R--- | M] (Coupons, Inc.) -- C:\WINDOWS\System32\cpnprt2.cid [2011/03/12 13:39:15 | 000,054,016 | ---- | C] () -- C:\WINDOWS\System32\drivers\uouk.sys [2010/12/02 22:11:56 | 000,296,247 | ---- | C] () -- C:\WINDOWS\System32\shimg.dll :Commands [purity] [emptytemp] [emptyflash] [Reboot]